Why this decision matters
Most successful attacks on small businesses are not targeted; they are harvested — a phished password, an unpatched system, a login with no second factor, found by automated scanning at scale. The encouraging corollary: a modest baseline of controls removes you from the harvest.
The Canadian Centre for Cyber Security publishes baseline controls specifically for small and medium organizations. The list below follows that philosophy, ordered by impact.
The central idea
Multi-factor authentication, tested backups, and prompt patching defeat the majority of real-world attacks on small firms.
The first tier is non-negotiable. Multi-factor authentication on email, banking, accounting, and remote access — email above all, because a compromised inbox is the master key to password resets and payment fraud. Backups that are automatic, kept offline or immutable where ransomware cannot reach them, and actually tested by restoring — an untested backup is a hope, not a control. Updates applied promptly to operating systems, browsers, and applications, with auto-update on wherever possible.
The second tier hardens the human and administrative layers: a password manager enabling unique passwords everywhere; administrator rights removed from daily-use accounts; staff trained — briefly, regularly — to recognize phishing and to verify payment instructions by phone; offboarding that revokes access the day someone leaves; and a one-page incident plan naming who to call — your IT support, your bank, the Cyber Centre, your insurer — before the bad day arrives. Cyber insurance, increasingly, both backstops and enforces this baseline.
Educational use notice
This publication is part of the Numera Decision Library and is provided for education only. It is general information — not accounting, tax, legal, or investment advice — and it does not consider your personal circumstances. Every guide is grounded in official guidance from government and regulated authorities — including the Canada Revenue Agency (CRA), the Department of Finance Canada, Service Canada and Employment and Social Development Canada, the Internal Revenue Service (IRS), and the Canadian Centre for Cyber Security — with the sources listed at the end of each guide. Tax rules and dollar limits change; confirm current figures with the official source, and speak with a qualified professional before acting on any decision discussed here.
Official references
Sources are official government and regulated-authority publications. Official sites reorganize periodically — search the document title if a link has moved.